Unauthenticated File Access Vulnerability in MCP Atlassian for Confluence and Jira
CVE-2026-77248

8.6HIGH

Key Information:

Vendor

Sooperset

Vendor
CVE Published:
22 September 2026

What is CVE-2026-77248?

The MCP Atlassian server for Confluence and Jira has a vulnerability that allows unauthenticated network users to access files stored within the MCP process. Specifically, the transport mechanism accepts requests without requiring user validation and reverts to operator credentials, which introduces a risk of sensitive data exposure. Additionally, the file upload feature permits unrestricted file path parameters, enabling attackers to upload malicious content to user-defined Jira issues or Confluence pages. This vulnerability affects versions prior to 0.22.0 and has been addressed in the latest release, where the input validation process has been strengthened to mitigate these risks.

Affected Version(s)

mcp-atlassian < 0.22.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.